CVE-2026-65100

Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.


We have discovered 399 live websites that are affected by CVE-2026-65100.

Run a Free Instant Scan




Affected Software

Product  ATS
Category Web Servers
Vulnerable Domains399 live websites (38% of ATS install base)
Vulnerable Versions
  • from 8 through 8.1.9
  • from 9 through 9.2.14
  • from 10 through 10.1.3
Vulnerable Versions Count15 versions ( 60% of all versions)


Common Weakness Enumeration

CWE-696 Incorrect Behavior Order



Details

  • Published - Jul 29, 2026
  • Updated - Jul 29, 2026

Credits

  • Omkhar Arasaratnam (reporter)
  • Apache Community (reporter)

Website Distribution by Country

Number of websites using CVE-2026-65100
United States40 websites



Germany131 websites
China128 websites
GB37 websites
France11 websites
Russia11 websites
Isle of Man8 websites
Canada5 websites
Spain5 websites
Finland5 websites

Website Distribution by TLD

Number of websites using CVE-2026-65100
.com.cn91 websites
.com66 websites
.org29 websites
.cn23 websites
.de20 websites
.ru11 websites
.org.uk11 websites
.net10 websites
.it8 websites
.fi8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65100

Top websites that are affected by CVE-2026-65100. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.******.jp Japan**,***
***.**********.de Germany**,***
******.***.cn China**,***
*********.******.***.cn China**,***
******.**********.de Germany***,***
******.***.cn China***,***
*****.******.***.cn China***,***
***.***.**.uk GB***,***
****.******.***.cn China***,***
*****.****.******.community Germany***,***
See full domain list

FAQ

CVE-2026-65100 is Incorrect Behavior Order in ATS
A total of 399 websites have been identified as vulnerable to CVE-2026-65100, based on global website indexing conducted by WebTechSurvey.
The ATS is affected by the CVE-2026-65100 vulnerability.
ATS versions up to and including 10.1.3 are vulnerable to CVE-2026-65100.